CVE-2026-40685
In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation of \ skipping.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40685?
CVE-2026-40685 has a high severity rating due to the potential for an out-of-bounds heap write which can lead to denial of service or code execution.
How do I fix CVE-2026-40685?
To fix CVE-2026-40685, upgrade Exim to version 4.99.2 or later where the vulnerability is patched.
What software is affected by CVE-2026-40685?
CVE-2026-40685 affects Exim versions prior to 4.99.2 when JSON lookup is enabled.
What is the attack vector for CVE-2026-40685?
The attack vector for CVE-2026-40685 involves sending malformed JSON within untrusted headers that triggers the out-of-bounds write.
Can CVE-2026-40685 be exploited remotely?
Yes, CVE-2026-40685 can be exploited remotely if an attacker can send specially crafted emails to the vulnerable Exim server.